<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Block IP Addresses Based on IP Type Using a Dynamic Network Zone
Administration
Okta Classic Engine
Okta Identity Engine
Overview

The article clarifies how to configure a Dynamic Zone to block network traffic based on the IP address type. Dynamic Zones help protect accounts by blocking IP addresses that use Tor anonymizer proxies, which reduces the impact of attacks such as password spray attacks.

Applies To
  • Network Zone
  • Proxies
  • Password spray attack
Cause

An attacker uses random anonymizer proxy IP addresses for password spray attacks.

Solution

Follow these steps to create a Dynamic Zone that blocks specific IP types:

  1. Go to Security > Networks in the Admin Console.

  2. Click Add Zone > Dynamic Zone.

  3. Enter a name for the zone.

  4. Select the Block access from IPs matching conditions listed in this zone checkbox.

Add dinamic zone

  1. For IP type, select Any, Any Proxy, Tor anonymizer proxy, or Not Tor anonymizer proxy.

NOTE: The Dynamic Zone blocks any incoming traffic from proxy IPs that match the selected type. The accuracy of Tor proxy detection depends on a third-party vendor, which identifies IP addresses that use Tor. The proxy type is only used to evaluate whether a proxy is Tor or not.

  1. Click Save.

 

Related References

Loading
Block IP Addresses Based on IP Type Using a Dynamic Network Zone